PT-2026-26639 · Qnap · Qvr Pro

Fuzzinglabs

·

Publicado

2026-03-20

·

Atualizado

2026-04-15

·

CVE-2026-22898

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions QVR Pro versions prior to 2.7.4.14
Description QVR Pro is affected by a missing authentication check for critical functions, allowing remote attackers to gain access to the system. The issue allows attackers to bypass authentication and access QVR Pro surveillance systems. The vulnerability has a CVSS score of 9.3, indicating a critical severity. It is described as a 'network-accessible goldmine for instant system compromise'. No information is available regarding the number of potentially affected devices or real-world exploitation incidents.
Recommendations Update QVR Pro to version 2.7.4.14 or later.

Correção

RCE

Missing Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22898
ZDI-26-292

Produtos afetados

Qvr Pro